Omahub
← All plugins
Q

Perf Hub

by QAInsights

Guarded load tests and quick HTTP benchmarks from the Omarchy bar.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
6b9e6a2
Scanned
2 weeks ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:26

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S oha` on Arch Linux)
  • Docs sudo README.md:27

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S apache` provides `ab` on Arch Linux)

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6b9e6a2
Reviewed
2 weeks ago

The plugin is a guarded launcher for well-known load-testing tools. It does not install anything, does not run tests without explicit user confirmation, and its embedded Python/shell snippets are bounded, non-obfuscated, and used only for probing, history I/O, and project detection. The deterministic scan's sudo findings are in the README's install instructions for optional tools, not in executable plugin code.

  • The README contains `sudo pacman -S oha` and `sudo pacman -S apache` examples, but these are documentation-only install hints for optional tools and are not executed by the plugin.
  • The plugin launches user-selected test commands in a terminal via `bash -lc`; this is by design and requires the user to review and explicitly launch, but it means the user is responsible for the safety of the test scripts/targets they choose.
  • The embedded Python snippets (history reader/writer, Gatling detector) are defensive and bounded, but they are still executed via `python3`; a human should be aware that these are runtime code paths, not just build tooling.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/QAInsights/omarchy-perf-hub --enable
Developer Tools #bar #quickshell

Perf Hub

<p align="center"> <img src="assets/preview.png" alt="Perf Hub workbench preview" width="480"> </p>

Perf Hub puts guarded shortcuts for k6, Apache JMeter, Locust, Artillery, Gatling, oha, and ApacheBench in the Omarchy Quattro bar. Choose an existing test or project—or enter a URL for a quick benchmark—review the exact command, and explicitly launch it in your default terminal.

Perf Hub does not install tools, run tests without confirmation, parse results, or manage running load generators. Review a test's target and make sure you are authorized before generating traffic.

Requirements

  • Omarchy Quattro
  • Python 3 (used for bounded history I/O and Gatling project detection)
  • One or more supported tool setups:
    • These command-line tools must be available on your login-shell PATH:
    • Gatling projects use their own launcher:
      • npm projects require npx and @gatling.io/cli in package.json
      • Maven and Gradle projects can use an executable project wrapper or an installed build tool
      • sbt projects require an installed sbt
      • JVM projects require Java

Missing tools remain visible in the panel with a link to their official setup guide. Perf Hub deliberately avoids assuming that every tool has the same Arch package source.

Install

omarchy plugin add https://github.com/QAInsights/omarchy-perf-hub --enable

The plugin appears in the right section of the bar by default. Move it with:

omarchy bar move dev.dosa.perf-hub --section right

Use

Click the gauge icon, then choose a test file or project or enter a benchmark target:

  • k6: .js or .ts
  • JMeter: .jmx
  • Locust: .py
  • Artillery: .yaml, .yml, .js, or .ts
  • Gatling: choose the project directory; Perf Hub detects npm, Maven, Gradle, or sbt without executing project code
  • oha: enter an HTTP or HTTPS URL, then optionally set request count or duration, concurrency, rate limit, method, header, and request body
  • ApacheBench: enter an HTTP or HTTPS URL, then set request count and concurrency with optional time limit, timeout, method, header, and keep-alive

Recent files and projects reopen the review screen; they never run immediately. Cards show up to five recents with in-place expansion, detect stale paths, and allow single-click removal. JMeter has a separate GUI action, while Locust exposes a shortcut to its local web UI. Review offers one-click command copying to clipboard, opening files or projects in the default editor, and revealing in the file manager. Artillery supports local environment and target overrides plus desktop JSON file picking. Gatling splits npm and JVM readiness, and can optionally select a simulation by name; otherwise its launcher remains interactive. Tool cards display installed tool versions and use locally packaged SVG artwork under assets/ without fetching images at runtime.

Quick benchmark targets are entered directly in the review screen rather than selected from disk. Their URLs and options are deliberately not added to recents or launch history, so query tokens, headers, and request bodies do not enter Perf Hub's state file.

Gatling project detection recognizes:

  • npm projects containing @gatling.io/cli
  • Maven projects containing gatling-maven-plugin
  • Gradle projects applying io.gatling
  • sbt projects containing gatling-sbt

Detection is time-limited, does not execute project files, does not follow symlinks while inspecting src/, and caps the number and depth of entries it visits.

Perf Hub launches Community/local commands only. It does not collect Artillery Cloud or Gatling Enterprise credentials.

Open or close Perf Hub from a custom keybinding or CLI with optional tool and path hints:

omarchy-shell shell toggle dev.dosa.perf-hub '{}'
omarchy-shell shell toggle dev.dosa.perf-hub '{"tool":"k6"}'
omarchy-shell shell toggle dev.dosa.perf-hub '{"tool":"k6","path":"/path/to/test.js"}'

For example, this Hyprland binding opens Perf Hub with SUPER + ALT + P:

o.bind("SUPER + ALT + P", "Perf Hub", "omarchy-shell shell toggle dev.dosa.perf-hub '{}'")

The plugin never edits Hyprland configuration automatically; the binding is an explicit user-level customization.

Sample test files for all supported tools are available in the examples/ directory.

State and privacy

Perf Hub stores up to five recent file or project paths per tool and twenty launch-history entries in:

${XDG_STATE_HOME:-~/.local/state}/omarchy/dev.dosa.perf-hub/history.json

It does not persist generated commands, target URLs, credentials, or run output. History reads are limited to 64 KiB and reject symlinks, special files, and non-regular files before any data reaches QML. History can be cleared from the panel.

Development

Tool behavior is definition-driven in Model.js: each definition owns its selection type, probe, options, validation, argv builder, and working-directory policy. Project-style tools can add a detector strategy without adding tool-specific branches to Panel.qml. Reusable QML components keep probing, project detection, cards, review fields, history, and branding separate from panel orchestration.

Validate the manifest and repository layout:

omarchy plugin validate .

Run the model tests:

node --test tests/model.test.js

When qmllint is installed, validate QML against the Omarchy shell imports:

qmllint -I "$OMARCHY_PATH/shell" BarWidget.qml Panel.qml ToolAvailability.qml \
  ProjectDetector.qml ToolCard.qml ReviewPage.qml HeroBanner.qml HistoryPage.qml

For a local interactive test, place a normal copy of this repository under ~/.config/omarchy/plugins/dev.dosa.perf-hub/; plugin folders may not contain symlinks. Then rescan and inspect it:

omarchy-shell shell rescanPlugins
omarchy plugin list --json | jq '.[] | select(.id == "dev.dosa.perf-hub")'
omarchy-shell shell summon dev.dosa.perf-hub '{}'

Remove

omarchy plugin remove dev.dosa.perf-hub

Removing the plugin does not delete its small history file automatically.

License

MIT